T09 · Insecure Skill Coding Practices
- Location
SKILL.md:113- Finding
Bearer Credential Can Be Disclosed to an Attacker-Controlled Gateway
- Content
View full analysis
dict: """Execute a GreenHelix tool via the GreenHelix REST API.""" response = requests.post( f"{GATEWAY_URL}/v1", headers=headers, json={"tool": tool, "input": params}, timeout=30, ) response.raise_for_status() return response.json() ``` ### Technical Analysis The gateway URL is read directly from the `GREENHELIX_API_URL` environment variable. The code does not validate that the destination: - Uses HTTPS. - Belongs to an approved GreenHelix hostname. - Uses an expected port. - Does not redirect the request to another origin. The same request attaches `GREENHELIX_API_KEY` as a bearer credential. Consequently, control over the environment variable is sufficient to redirect the credential and request payloads to an arbitrary network endpoint. Although the document is an educational guide rather than an executable package, it describes its examples as production-ready. Deploying this implementation without additional validation would create a credential-exfiltration primitive. ### Attack Path 1. An attacker gains the ability to influence deployment configuration, a container environment, a CI/CD variable, or a generated `.env` file. 2. The attacker sets `GREENHELIX_API_URL` to an endpoint under their control. 3. The application initializes `GATEWAY_URL` from the modified value. 4. Any call to `execute()` sends an `Authorization: Bearer ...` header to the attacker-controlled endpoint. 5. The attacker captures the API key and reuses it against the legitimate GreenH ...[truncated 543 chars]- Remediation
View remediation
